planning-user-interviews
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill uses official PostHog tools to perform operations within the platform's ecosystem.
- [COMMAND_EXECUTION]: The skill provides read-only SQL (HogQL) templates to retrieve participant data from the PostHog database, which is a core function of the skill for audience targeting.
- [DATA_EXFILTRATION]: User data such as emails and distinct IDs are retrieved but remain within the PostHog environment to populate the interview topic models. No data is sent to external, non-vendor domains.
- [PROMPT_INJECTION]: The skill handles external data from SQL results and CSV inputs to populate interview contexts. While this represents a potential surface for indirect injection, the instructions are focused on legitimate research workflows within the platform.
Audit Metadata